CVE-2010-4243
Last modified
CVE-2010-4243 is a vulnerability of currently unknown severity. fs/exec.c in the Linux kernel before 2.6.37 does not enable the OOM Killer to assess use of stack memory by arrays representing the (1) arguments and (2) environment, which allows local users to cause a denial of service (memory consumption) via a crafted exec system call, aka an "OOM dodging issue," a related issue to CVE-2010-3858.. EPSS estimates a 0.91% chance of exploitation in the next 30 days.
Description
fs/exec.c in the Linux kernel before 2.6.37 does not enable the OOM Killer to assess use of stack memory by arrays representing the (1) arguments and (2) environment, which allows local users to cause a denial of service (memory consumption) via a crafted exec system call, aka an "OOM dodging issue," a related issue to CVE-2010-3858.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | < 2.6.37 |
References
- http://grsecurity.net/~spender/64bit_dos.cBroken Link
- http://lkml.org/lkml/2010/8/27/429Mailing List, Patch, Third Party Advisory
- http://lkml.org/lkml/2010/8/29/206Mailing List, Patch, Third Party Advisory
- http://lkml.org/lkml/2010/8/30/138Mailing List, Patch, Third Party Advisory
- http://lkml.org/lkml/2010/8/30/378Mailing List, Third Party Advisory
- http://openwall.com/lists/oss-security/2010/11/22/15Mailing List, Third Party Advisory
- http://openwall.com/lists/oss-security/2010/11/22/6Mailing List, Third Party Advisory
- http://secunia.com/advisories/42884Third Party Advisory
- http://secunia.com/advisories/46397Third Party Advisory
- http://www.exploit-db.com/exploits/15619Exploit, Third Party Advisory, VDB Entry
- http://www.redhat.com/support/errata/RHSA-2011-0017.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/520102/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/45004Third Party Advisory, VDB Entry
- http://www.vmware.com/security/advisories/VMSA-2011-0012.htmlThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=625688Issue Tracking, Third Party Advisory
- http://grsecurity.net/~spender/64bit_dos.cBroken Link
- http://lkml.org/lkml/2010/8/27/429Mailing List, Patch, Third Party Advisory
- http://lkml.org/lkml/2010/8/29/206Mailing List, Patch, Third Party Advisory
- http://lkml.org/lkml/2010/8/30/138Mailing List, Patch, Third Party Advisory
- http://lkml.org/lkml/2010/8/30/378Mailing List, Third Party Advisory
- http://openwall.com/lists/oss-security/2010/11/22/15Mailing List, Third Party Advisory
- http://openwall.com/lists/oss-security/2010/11/22/6Mailing List, Third Party Advisory
- http://secunia.com/advisories/42884Third Party Advisory
- http://secunia.com/advisories/46397Third Party Advisory
- http://www.exploit-db.com/exploits/15619Exploit, Third Party Advisory, VDB Entry
- http://www.redhat.com/support/errata/RHSA-2011-0017.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/520102/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/45004Third Party Advisory, VDB Entry
- http://www.vmware.com/security/advisories/VMSA-2011-0012.htmlThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=625688Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-4243?
How severe is CVE-2010-4243?
How do I fix CVE-2010-4243?
Are you affected by CVE-2010-4243?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
